Django 1.4.6 release notesÂś
August 13, 2013
Django 1.4.6 fixes one security issue present in previous Django releases in the 1.4 series, as well as one other bug.
This is the sixth bugfix/security release in the Django 1.4 series.
Mitigated possible XSS attack via user-supplied redirect URLsÂś
Django relies on user input in some cases (e.g.
django.contrib.auth.views.login(), django.contrib.comments, and
i18n) to redirect the user to an âon successâ URL.
The security checks for these redirects (namely
django.utils.http.is_safe_url()) didnât check if the scheme is http(s)
and as such allowed javascript:... URLs to be entered. If a developer
relied on is_safe_url() to provide safe redirect targets and put such a
URL into a link, they could suffer from a XSS attack. This bug doesnât affect
Django currently, since we only put this URL into the Location response
header and browsers seem to ignore JavaScript there.
BugfixesÂś
- Fixed an obscure bug with the
override_settings()decorator. If you hit anAttributeError: 'Settings' object has no attribute '_original_allowed_hosts'exception, itâs probably fixed (#20636).